Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2017-13312 In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escal… Android Mitigation only Fix from $1,9502024-11-15 HIGH 7.8 CVE-2017-13314 In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul… Android Patch available Fix from $1,9502024-11-15 HIGH 7.8 CVE-2024-46462 By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform task… Mitigation only Fix from $1,9502024-11-15 HIGH 7.8 CVE-2024-46463 By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks… Mitigation only Fix from $1,9502024-11-15 HIGH 7.8 CVE-2024-46465 By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks… Cryhod after 2024.3 Fix from $1,9502024-11-15 HIGH 7.8 CVE-2024-46466 By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other use… Mitigation only Fix from $1,9502024-11-15 HIGH 7.8 CVE-2024-46467 By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform ta… Mitigation only Fix from $1,9502024-11-15 HIGH 8.0 CVE-2024-52551 Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a bui… Pipeline\ after 2.2214.vb_b_34b_2ea_9b_83 Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-35201 Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of priv… Server Debug And Provisioning Tool Mitigation only Fix from $1,9502024-11-13 MEDIUM 6.7 CVE-2024-29083 Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authenticated user to potentially … Mitigation only Fix from $1,6002024-11-13 MEDIUM 6.7 CVE-2024-25647 Incorrect default permissions for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow an authenticated user t… Mitigation only Fix from $1,6002024-11-13 HIGH 7.2 CVE-2024-21820 Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user… Mitigation only Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43085 In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic … Android Patch available Fix from $1,9502024-11-13 MEDIUM 5.5 CVE-2024-43086 In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused… Android Patch available Fix from $1,6002024-11-13 HIGH 7.8 CVE-2024-43089 In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-40660 In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the code. This c… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-40661 In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission chec… Android Patch available Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-43081 In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This c… Android Patch available Fix from $1,9502024-11-13 HIGH 7.0 CVE-2024-49504 grub2 allowed attackers with access to the grub shell to access files on the encrypted disks. Mitigation only Fix from $1,9502024-11-13 HIGH 7.3 CVE-2024-21957 Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentiall… Management Console 10.0+ Fix from $1,9502024-11-12 HIGH 7.3 CVE-2024-21958 Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potenti… Provisioning Console 4.0.0.408+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-21938 Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could… Management Plugin For Sccm 7.0.0.1318+ Fix from $1,9502024-11-12 HIGH 7.3 CVE-2024-21939 Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privil… Cloud Manageability Service 2.0.0.232+ Fix from $1,9502024-11-12 HIGH 7.3 CVE-2024-21945 Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation… Ryzen Master Monitoring Software Development Kit 2.13.0.2915+ Fix from $1,9502024-11-12 HIGH 7.3 CVE-2024-21946 Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potent… Ryzen Master Utility For Overclocking Control 2.13.1.3097+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-21937 Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting… Radeon Software 24.q2 / 24.6.1+ Fix from $1,9502024-11-12 MEDIUM 5.4 CVE-2024-46894 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorizatio… Sinec Ins after 1.0 Fix from $1,6002024-11-12 MEDIUM 5.3 CVE-2024-43430 A flaw was found in moodle. External API access to Quiz can override contained insufficient access control. Moodle 4.4.2+ Fix from $1,6002024-11-11 HIGH 7.8 CVE-2024-50590 Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one o… Mitigation only Fix from $1,9502024-11-08 CRITICAL 9.8 CVE-2023-27195 Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve the last registration access co… Mitigation only Fix from $2,3002024-11-08